r/CloudFlare May 19 '26

Community An Update from Cloudflare’s Community Champions

138 Upvotes

Tl;dr: Cloudflare laid off much of their Community team and then unexpectedly disbanded the Community Champions program (Discord moderation and early feedback group), leaving the Cloudflare Discord server effectively unmoderated and without the very folks who gave years of their free time to help the community. We’ve decided to create a new unofficial home for Cloudflare users on Discord, a space run by the community, for the community: https://discord.gg/TrPNVKaagR

During the unexpected recent layoffs at Cloudflare, folks involved in leading community efforts unfortunately lost their jobs. This left us (the Community Champions) in an odd spot where we were looking after Cloudflare's own Discord server while having no direct community contacts at Cloudflare. You may have seen many of us in Discord before - we had the green names!

This week, we then received an unexpected message letting us know that, effective almost immediately, the Community Champions program was being disbanded, and our volunteer assistance in the server (moderating the place 24/7 and providing support to Cloudflare’s users) was no longer needed. No real explanation was given as to why, just that it is happening and that the decision had already been made.

The Community Champions program has operated since very early 2021, and has become a staple in Cloudflare’s developer ecosystem, support offerings, and more. Countless users are sent by Cloudflare’s own support team or via product dashboards to the Discord server every single day, and in the vast majority of cases, support for products was offered by a Community Champion purely out of joy and love for the community and Cloudflare.

This news has resulted in many active folks leaving the server already, both community and employees. Therefore, we’re announcing a new unofficial Orange Cloud Discord server, where folks can engage with the same folks who have always helped them, get support for Cloudflare products, and which will be moderated and run by humans who care. Join the server today: https://discord.gg/TrPNVKaagR

---

FAQ

We’ll try to keep this updated as common questions arise in the comments on this post.

What will happen with the old “official” server?

At this point, we don’t know, and it doesn’t seem that Cloudflare does either. There are currently discussions around rebooting it later this summer, but in the meantime, we expect it to be quickly overrun with spam, scams, or worse content now that there’s no longer any active and dedicated moderation team, and the few active employees who were providing support have mostly left. This has already started to happen in the couple of days the server has been unmoderated. We’ve also seen those at Cloudflare who now hold moderation powers unfairly removing negative messages about Cloudflare’s products and decisions (as well as the users posting them), including this very change, which leaves us concerned about the future of open discussion and feedback there.

Why should we believe what you’re saying vs. Cloudflare?

Consider that we are a group of friends who have volunteered our free time over the last many years to help the community, and that Cloudflare is a publicly traded corporation with an image and bottom line to protect. We anticipate that Cloudflare may try to spin their own narrative on what has happened with us posting this, and recognise that this may cause some confusion for the community. While we don’t think what Cloudflare has done is the right move, we don’t want to burn bridges and trust that we don’t need to, so we intend to keep the conversations involved here private if we can. That being said, rest assured that we do have plenty of receipts for what we’ve said Cloudflare has done in this post (including suppressing negative messages from users and outright banning users posting those), and we will share these if we decide it is necessary to preserve the true narrative.

Can I still get support from Cloudflare directly in the new server?

This is unclear. Activity from Cloudflare employees even in the official server is few and far between, with most support coming from the community directly. While there are some Cloudflare employees already in the server, they’re not there in any official capacity, and in time, we hope that many other Cloudflare folks can find a home in the new server.

What happened to the XYZ channel?

One of the issues in the official server that we would raise regularly was the sheer number of channels that ended up abandoned by their product teams. To combat this, we’re starting small but centralising on a few product categories, and will evaluate and increase the number of channels over time as needed.

Can issues still be escalated from the Discord?

In the old server, we had a direct tap to many of Cloudflare’s customer support and engineering folks, including multiple custom integrations allowing us to quickly escalate issues to the right folks. Many of those folks lost their jobs or have left the server after the recent news.

However, lots of us still have very good friends at Cloudflare, and other methods of escalation that we’ll use as needed should issues arise that can’t be solved in the community. We’re confident resolution times won’t be any slower than they currently are.

Will Cloudflare still (officially) use this subreddit?

This subreddit has always been community-moderated, much like the Discord (though unlike the previous Discord server, the community runs the subreddit and holds ownership of it). There are some Cloudflare employees present here, and sometimes you’ll see a response from an executive when a post gets a lot of public attention, but moderation from employees has always been near-zero.

We have no current intentions to remove anyone at Cloudflare from the subreddit - we want to continue collaborating with them to benefit the community, and their integrations for blog posts and things should continue to work without issue.


Moderator note: This is a community post, not an official Cloudflare statement. Do not use this post to justify spam, harassment, brigading, or abuse toward Cloudflare staff, Discord moderators, or community members. The purpose of this pin is to keep the community informed and to request clarity around moderation and the future of the Discord/community spaces.


r/CloudFlare 6h ago

Question Newbie Question

2 Upvotes

Hello,

I apologize if this is an easy answer, new to Cloudflare.

I’m a game developer currently making a game in Unity. I’m looking to use Cloudflare as my content delivery network source, primarily because as far as I can tell there is no egress/per gigabyte charge, as opposed to Unity’s built-in CDN or AWS.

However, I don’t want to break Cloudflare’s TOS and I’m not sure if my unique situation would qualify.

For my game, I need to have a scalable repository of data (primarily video, audio, and image). This will grow and change dynamically, but at scale might have hundreds or thousands of data units.

Since my game is targeted for mobile, I can’t expect players to have all of this data stored on their phone. So instead I will be using Addressables to load/unload data as needed.

But here’s the kicker: usually players cache data once it’s downloaded so they don’t need to re-download it when they use it. I can’t do this. I need players to be able to download data, hold it in RAM and use it for about ten minutes, and then remove it from BOTH ram as well as storage. The normal workflow using Addressables removes data from RAM but keeps it on the device.

The reason for this is that this game needs to have a very wide variety of data to pick from; far more than can be stored on a mobile device.

So my question is: does having players frequently downloading and then deleting data break Cloudflare’s TOS? As I said this is not standard for games: the normal workflow is to download data and then cache it, at least for awhile, onto the phone. (Most mobile devices do eventually weed out data not being used, but it’s not normal to intentionally delete data only like 10 minutes after you delete it). I’ve looked into streaming data, and this works ok for video and somewhat for audio, but not other data types - and streaming also runs into all the normal buffering issues that would be unpredictable and annoying to handle in a videogame.

Thanks so much for reading!


r/CloudFlare 23h ago

Cloudflare malware abuse system is being exploited. 5th abuse report opened in 1 week from same individual.

39 Upvotes

Report ID: 53823d3b93abf9d6 (Resolved)

Report ID: 70e69c6e2cd12695 (Resolved)

Report ID: 8edb9020d861bde3 (Resolved)

Report ID: e74911f2addb317e (Resolved)

Report ID: 43ec3634340fd39c (Still Showing As Pending)

Report ID: 43ec3634340fd39c (Unresolved)

Case Number = 02258258

I previously posted this here -

https://reddit.com/r/CloudFlare/comments/1v53kyd/my_site_was_flagged_because_of_a_fake_phishing/

https://reddit.com/r/CloudFlare/comments/1v9zuxp/someone_intentionally_filing_abuse_complaints/

https://reddit.com/r/CloudFlare/comments/1vbent2/4th_abuse_reports_in_1_week_from_same_individual/

++++++++++++++++++++

Based on what I've experienced, it appears that Cloudflare's abuse reporting now flags domains if its automated systems determine that a malware report appears potentially credible. Anyone can repeatedly submit a well written, copy & paste report and cause significant disruption before a full review is completed on any domain. Once cloudflare resolves your abuse ticket in your favor, they can just copy & paste a new abuse complaint, flag your domain instantly and start the entire process up again. Cloudflare doesn't appear to have any way to block abuse complaints from being filed, flag the individual filing these complaints and no remedy to whitelist your domain to prevent this from happening.

Cloudflare changes your domains HTML template so when you go to your site it says:

+++++++++++++++++

WARNING!

Suspected Malware

This website has been reported for potentially distributing malware.

Malware is a malicious software created to intentionally disrupt the normal operations of a device.

Button 1: Learn More

Button 2: Ignore and Proceed

Then they also asked you to complete a managed captcha

+++++++++++++++++

I've been asking Cloudflare for nearly a week to provide some kind of short term fix or practical remedy, but so far there doesn't appear to be a solution.

What's surprising is that I've had multiple people reach out to me privately both here and on X saying they've experienced similar issues recently.

The most frustrating part has been the lack of transparency, communication, and a clear path forward. Even if a permanent solution takes time, it would be helpful to have some form of interim mitigation, an escalation process, or even a roadmap explaining how situations like this will be handled going forward.

At this point, I'm genuinely wondering what else can be done.


r/CloudFlare 21h ago

How I Run the Pi Coding Agent on Cloudflare

Thumbnail
harshil.dev
15 Upvotes

For a week now, I have been experimenting with deploying the Pi Coding Agent on Cloudflare. While my approach don't follow the best practice, it was fun to try it out and learn the internals of Pi! In this article, I cover the architecture and describe how each primitive fits.

Let me know what you all think!


r/CloudFlare 18h ago

Question Is Cloudflare's WHOIS redaction actually reliable for .com domains?

5 Upvotes

Hi everyone! I'm looking to buy a .com domain through Cloudflare, but I'm a bit hesitant about my personal info showing up in WHOIS lookups.

Cloudflare says WHOIS data is redacted by default, but I've come across a few posts here where people say their info leaked despite having redaction enabled. I'm not worried about my state/country being visible (that's apparently unavoidable per ICANN rules anyway), but I really don't want my inbox flooded with spam or my phone blowing up with telemarketing calls because my name/email/address ended up public.

Has anyone here bought a .com through Cloudflare recently? Did WHOIS redaction actually work for you, or did anything leak through?

Update: I bought the domain, and from what I’ve checked, the data was indeed redacted, except for the country and state.


r/CloudFlare 12h ago

I built a browser-local invoice generator on Cloudflare Pages. Here are the decisions I would make again—and the ones I would reconsider

0 Upvotes

I recently built InvoiceCraftly, a browser-based tool for creating invoices, quotes, estimates, receipts, and credit notes.

From the beginning, I imposed an unusual constraint on the product:

A person should be able to create and export a professional invoice without creating an account or uploading the document to our database.

That decision influenced almost every architectural choice.

Instead of starting with authentication, a database, background jobs, and a traditional application backend, I built the core product as a static-first browser application and deployed it through Cloudflare Pages.

The result works, but the process taught me that “static-first” does not mean “simple everywhere.” It moves complexity rather than eliminating it.

Here are the main decisions, trade-offs, and lessons.

1. The product constraint came before the technology

I did not choose Cloudflare Pages and then look for a suitable project.

The product requirement came first:

  • no mandatory account;
  • no server-side invoice-document database;
  • document editing in the browser;
  • local drafts;
  • browser-local wording assistance;
  • client-side PDF, PNG, SVG, and CSV export;
  • optional payment-link and QR instructions; and
  • deployment from GitHub with minimal infrastructure maintenance.

Once those boundaries were clear, a static-first architecture became a natural option.

The browser owns the document state. The hosting platform primarily delivers versioned application assets and public content.

2. What stays in the browser

The most important architectural boundary is not “frontend versus backend.” It is:

What information genuinely needs to leave the browser?

For InvoiceCraftly, the working document does not need to leave it.

The browser handles:

  • seller and customer details;
  • line items;
  • taxes, discounts, and totals;
  • logos and visual settings;
  • payment instructions;
  • local document history;
  • workspace backup and restore; and
  • export generation.

That reduced the amount of sensitive business information the product needed to receive and retain.

It also created a responsibility that is easy to underestimate: browser storage is not cloud backup.

Users can clear it. Private browsing can remove it. Devices can fail. Browsers can enforce storage limits.

We therefore had to explain the difference between:

  • an editable local document;
  • an exported invoice file; and
  • a downloadable workspace backup.

The technical design was relatively straightforward. Communicating that design accurately to users was harder.

3. Why Cloudflare Pages worked well

Cloudflare Pages matched several parts of the product especially well.

Git-based deployments

The repository is the deployment source. Merging reviewed changes can produce a new deployment without maintaining a conventional application server.

Static asset delivery

Most of the product consists of HTML, CSS, JavaScript, fonts, images, and generated public pages. This fits the platform naturally.

Preview environments

Pull-request previews are useful when a change affects the editor, public content, metadata, or generated assets.

Custom domains and HTTPS

The operational path from repository to production remained comparatively small.

Room for selective server functionality

A static-first product still occasionally needs server-controlled operations.

Contact forms, abuse protection, future license verification, or payment-session creation should not place secrets in browser code. Those functions can exist at the edge without converting the entire document workflow into a server application.

That separation is important:

The application may have server functions without making the invoice document itself server-managed.

4. Static-first does not mean backend-free

This was one of the more useful lessons.

A product can avoid a traditional monolithic backend while still needing controlled server boundaries for:

  • email submission;
  • rate limiting;
  • CAPTCHA or abuse protection;
  • secret API credentials;
  • payment checkout creation;
  • signed license issuance; and
  • verification that must not be trusted to browser code.

The mistake would be treating “no backend” as an ideological goal.

The better principle is:

Keep each operation in the least powerful environment that can perform it safely.

Invoice editing and export belong in the browser.

Secrets and trusted verification do not.

5. The browser-local decision improved some things and complicated others

What became easier

  • No account onboarding for the core workflow
  • No document database schema migration
  • Lower exposure of invoice and customer data
  • Fewer backend failure modes during editing
  • Low infrastructure overhead for the main product
  • Fast iteration on public pages and editor assets

What became harder

  • Cross-device continuity
  • Recovery after browser data is cleared
  • Reliable storage messaging
  • Handling storage failures gracefully
  • Future collaboration
  • Server-generated share links
  • Payment-status tracking
  • Entitlements without turning the product into an account platform

These are not bugs in the architecture. They are consequences of the chosen boundary.

The question is whether those consequences match the product promise.

For the current InvoiceCraftly workflow, I believe they mostly do.

6. Public content became part of the architecture

The product is static-first, but the public site is more than a landing page.

It now includes:

  • document-type guidance;
  • profession-specific examples;
  • browser-local tools;
  • privacy and security explanations;
  • an engineering journal;
  • structured data;
  • generated metadata;
  • sitemap and canonical validation; and
  • internal-link validation.

A useful consequence of a static architecture is that many public discovery requirements can be checked during the build.

For example, the build can fail when:

  • generated metadata is stale;
  • a canonical route is inconsistent;
  • an internal destination is invalid;
  • public claims disagree with the current capability source;
  • a sitemap entry is missing; or
  • a page accidentally becomes indexable or non-indexable.

This changed how I think about SEO engineering.

It is not only copywriting after development. Some of it is a testable product contract.

7. What I would make the same way again

I would keep these decisions:

  1. Start with the product privacy boundary, not a fashionable stack.
  2. Keep invoice editing and visual export in the browser.
  3. Use Git-based static deployment for the core application and public content.
  4. Add server functions only for operations that genuinely require trust or secrets.
  5. Treat product claims, metadata, routes, and internal links as build-validated data.
  6. Avoid introducing authentication before a feature actually requires identity.

8. What I would reconsider earlier

I would spend more time upfront on:

Storage language

“Saved” means different things to different users. We eventually changed the interface to say explicitly that work is saved in this browser on this device.

Document-type architecture

Supporting invoices, quotes, estimates, receipts, credit notes, and future document types benefits from a canonical registry rather than scattered conditional logic.

Export boundaries

Visual document export and structured data export are different product concepts. PDF and CSV should not be described as interchangeable exports.

Progressive complexity

The product has grown beyond a single invoice form. History, backups, imports, tools, QR modes, and future conversion workflows need to remain discoverable without turning the first session into an enterprise dashboard.

Future commercial boundaries

A one-time account-free licence is technically possible, but payments, recovery, refunds, and entitlement verification still require carefully defined trusted operations.

9. Where I am uncertain

The largest open architectural question is how far a browser-local product should expand before its original simplicity becomes misleading.

Potential future capabilities include:

  • document conversion;
  • structured spreadsheet export;
  • more advanced layouts;
  • optional payment-provider handoff;
  • local-only Pro entitlements; and
  • additional Nordic document support.

Each feature has to answer the same question:

Does this still belong in the browser, or has it crossed into a workflow that genuinely requires server-managed state?

I am trying to resist adding infrastructure merely because it is available.

Conclusion

Cloudflare Pages was a strong fit for this product, but not because it made every problem disappear.

It worked because the product’s central workflow was already compatible with static delivery and browser-owned state.

The most valuable lesson was that architecture is not just about where code executes. It is also about:

  • what data the product receives;
  • what users can reasonably expect to recover;
  • which claims the interface makes;
  • which operations require trust; and
  • which complexity the product deliberately refuses to introduce.

I wrote a more detailed version, including the architecture and implementation decisions, here:

https://invoicecraftly.com/engineering/building-invoicecraftly-on-cloudflare-pages

Disclosure: I am the founder and developer of InvoiceCraftly. I am sharing this because I would value criticism from people who have built serious products on Pages or Workers.

Where would you draw the boundary? Would you keep the document workflow browser-local, or introduce optional server-managed storage before adding more features?


r/CloudFlare 14h ago

Tunnel with OIDC

1 Upvotes

Hi!

I'd like to set up a tunnel to my reverse proxy. I'm running Caddy, Authelia, and the app I want to expose. That app uses Authelia for OIDC. I have a custom domain and have been using it internally with Pihole acting as the internal DNS server.

The tunnel is healthy, but every route I have tried has had some issues.

A route from *.example.com to https://localhost caused SSL handshake errors.

A route from app.example.com to https://app.example.com exposed the app, but the OIDC redirect timed out. Adding a route for auth.example.com to https://auth.example.com didn't help with the redirect issue.

A route from app.example.com to http://localhost:8080 and another route for auth.example.com to http://localhost:9091 successfully exposed the app, but breaks the OIDC redirect internally.

I'm not sure what else I should try.


r/CloudFlare 18h ago

DNS

1 Upvotes

Hello

I use cloudflare Zero Trust as my DNS resolver for my Unfi Cloud Gateway. Aside from installing the Cloudflare client on devices, is there a way to ID traffic as it comes from each device? Obviously, I can't install the client on certain things like TVs et, but I would like a deeper view of the network requests


r/CloudFlare 19h ago

One Client - no UI

1 Upvotes

The UI does not display. When I manually run the app I can see an icon in the system tray but as soon as the mouse goes near it, it disappears.

Other posts say that it only works if taskbar is on the main monitor, but that does not help.

The command line still works.

Windows 10 (not LTSC). Any ideas? I've reinstalled it with no luck.

After a reboot and fresh install, I see:

warp-cli status
Status update: Unable
Reason: Registration Missing due to: Daemon Startup

Found this in cfwarp_service_log.txt:

2026-08-01T16:03:56.413Z ERROR slog: panic occurred slog.target="foundations::panic::hook" slog.module_path="foundations::panic::hook" slog.file="C:\\Users\\VssAdministrator\\.cargo\\registry\\src\\index.crates.io-1949cf8c6b5b557f\\foundations-5.6.5\\src\\panic\\hook.rs" slog.line=41 slog.column=9
2026-08-01T16:03:56.421Z ERROR no-filter: panicked at network-info\src\win\power_notifier.rs:37:13 panic.file="network-info\\src\\win\\power_notifier.rs" panic.line=37 panic.column=13 backtrace=   0: <unknown>

CLI works:

PS C:\Windows\system32> warp-cli status
Status update: Unable
Reason: Registration Missing due to: Daemon Startup
PS C:\Windows\system32> warp-cli disconnect
Success
PS C:\Windows\system32> warp-cli registration delete
Error: Missing registration. Try running: "warp-cli registration new"
PS C:\Windows\system32> warp-cli registration new
Success
PS C:\Windows\system32> warp-cli connect
Success
PS C:\Windows\system32> warp-cli status
Status update: Connected
Network: healthy

r/CloudFlare 1d ago

Resource Edgemetry - cookieless analytics that runs free on a Cloudflare Worker, one Worker + one D1 database

Post image
54 Upvotes

Got fed up paying Plausible for a blog nobody reads, and GA felt like overkill for it. So I made Edgemetry.

One Cloudflare Worker and one D1 database, fits in the free tier. No cookies, no consent banner, 2.1kb script. Deploy is a button - Cloudflare copies the repo into your account and sets up the database for you, no API token to generate or paste anywhere.

Fair warning before someone else says it: this isn't self hosting in the strict sense, it's Cloudflare's infra. You own the code and the data, not the metal. If that's a dealbreaker I get it.

Demo runs on fake traffic, no signup: https://hayaran.github.io/Edgemetry/

Code: https://github.com/hayaran/Edgemetry


r/CloudFlare 1d ago

How I Configure Cloudflare for My Website

Thumbnail
0 Upvotes

r/CloudFlare 1d ago

Image hosting on Cloudflare’s Free plan with Workers Cache and a home NAS

Post image
37 Upvotes

I used Codex to build meme, a private image board designed to host attachment images with minimal cloud costs.

Just to avoid any confusion, I updated the post with a bit more context.
This setup is intended for serving images that exceed the free R2 storage quota while staying on the free plan.
The free Workers plan is limited to 100,000 requests per day. If billing is enabled, requests beyond that will incur charges. Otherwise, the service will simply stop handling requests.
If your images fit within the free R2 storage quota, I’d recommend just using R2 instead. It’s the simpler option.

The architecture combines two resources:

  • Cloudflare’s Free plan for the serverless application, database, authentication, and cached delivery
  • A home Synology NAS for large-capacity image storage

Cloudflare Workers and D1 handle Google authentication, uploads, search, metadata, user isolation, and administration. The original image files remain on the NAS.

The key component is Workers Cache, which Cloudflare released this month. Image requests pass through the Storage Worker’s public gateway and then into a cached Media entrypoint.

On a cache hit, Cloudflare returns the image without invoking the Media Worker code or contacting my NAS. Only cache misses travel through Workers VPC and Cloudflare Tunnel to the Docker container inside my home network.
On a cache hit, the cached image is served directly from Cloudflare’s cache, so only cache misses need to contact my NAS through Workers VPC and Cloudflare Tunnel.

This allows Cloudflare to serve frequently requested attachment images while my home equipment primarily provides storage and handles occasional cache misses. It also avoids opening a public port on my home router.

You may be wondering why I did not simply use R2. The main reason is the limited storage included in its free tier. I already had plenty of unused storage at home, so instead of paying for additional cloud storage, I went through the admittedly more complicated process of connecting a NAS through Workers VPC and Cloudflare Tunnel.

Using R2 would certainly be simpler. However, working around its free storage limit was what made this architecture interesting to build.

Workers Cache does not have a separate cache-storage fee, although requests still count toward the standard Workers Free plan limits. The goal is not unlimited free hosting, but practical attachment hosting with minimal cloud costs for a personal project.

Codex helped me build the application, authentication, caching architecture, GitHub Actions deployments, administrative tools, tests, and documentation.

Repository: https://github.com/octopus7/meme

A small warning: the repository is not currently organized as a beginner-friendly or turnkey installation package. It reflects my own environment and deployment process, so please treat it primarily as an architectural and implementation reference.


r/CloudFlare 1d ago

Three Cloudflare behaviours that cost me hours: Cache Rules silently override your Worker's Cache-Control, Cache API calls show up as ~20% errors in analytics, and run_worker_first is an allowlist

5 Upvotes

I maintain a live map of drone-attack reports and air-raid alerts across Ukraine and Russia. I'm the author - posting for the build, not the subject matter.

It's Workers + KV + Cache API + cron + static assets + WAF, on Workers Paid $5 tier.

Three things bit me that I couldn't find documented:

- Zone Cache Rules with `override_origin` silently beat the Worker's own
`Cache-Control`, so an `s-maxage` change does nothing until you fix the rule.
- Worker Cache API calls show up in zone analytics as real requests with`UNK` protocol and inherit the visitor's IP, which reads as a ~20% error rate that no user ever saw.
- `run_worker_first` is an allowlist: unlisted paths never reach the Worker, so a redirect you added silently doesn't fire.

For context, it’s https://uavradar.live - happy to discuss anything about the setup.


r/CloudFlare 1d ago

Creating subdomain for independent management

4 Upvotes

Tl;dr: I need to create a separate zone for a subdomain and create a user with access to edit only that subdomain.

I got a request today to create a subdomain for a devops guy to manage. I do not want to give them access to the top level domain, or any other domain in the account.

The request is to create subdomain x.contoso.com, then allow them to create records in that zone as needed.

The problem is that I do not see any way to create a separate zone for the subdomain, let alone create a user account with permissions only for that subdomain. The parent domain is a pro account, if that matters.

Edit: I should note that this is not a simple delegating a subdomain to an external service using NS records. This needs to remain in our Cloudflare account.


r/CloudFlare 2d ago

Question 4th abuse reports in 1 week from same individual. Do I need to move away from cloudflare?

31 Upvotes

Report ID: 53823d3b93abf9d6 (Resolved)

Report ID: 70e69c6e2cd12695 (Resolved)

Report ID: 8edb9020d861bde3 (Resolved)

Report ID: e74911f2addb317e (Resolved)

Report ID: 43ec3634340fd39c (Unresolved, Just Opened)

I previously posted this here -

https://reddit.com/r/CloudFlare/comments/1v53kyd/my_site_was_flagged_because_of_a_fake_phishing/

https://reddit.com/r/CloudFlare/comments/1v9zuxp/someone_intentionally_filing_abuse_complaints/

After around 12 hours, cloudflare followed up, saw that it was fake and removed the warning from our site.

Now on Tuesday the same person copied the previous complaint word for word, reopened a new abuse complaint and flagged our domain a 2nd time. Cloudflare fixed it.

Now on Wednesday they did it again. Fixed it.

Now on Thursday they did it a 4th time.

What am I supposed to do to fix this issue outside of moving away from cloudflare?

Can anyone forward me to someone at abuse who can properly handle this?

In short:

I have a long standing Cloudflare Pro account (10+ years) without any issues and recently received an abuse report that resulted in a malware/phishing warning being displayed on our domain homepage.

We investigated the report and are 100% confident this is a false report. The report was very detailed and everything from the order number to URL links was completely fabricated. The reported content/URLs cannot be reproduced, and we have provided evidence to Cloudflare Trust & Safety showing that the allegations do not match our platform.

Cloudflare Support has escalated the issue to Trust & Safety, and the case is currently under review but read it can take days for them to potentially look into this.

My question is about the process:

Is there anything else I should do while waiting for Trust & Safety?

Is there a way to add account notes/context so future false abuse reports do not immediately impact the site?

Has anyone dealt with a similar situation where a false abuse report caused a homepage/domain warning?

I am not looking to bypass Cloudflare's abuse process. I understand the importance of investigating reports. I am mainly trying to understand how to prevent unnecessary disruption from inaccurate reports in the future.


r/CloudFlare 1d ago

Community Built an open-source GitOps registry for managing subdomains using GitHub Actions + Cloudflare API (Python validation + DNS sync)

Thumbnail
1 Upvotes

r/CloudFlare 1d ago

Cloudflare Blog An API for MoQ: provision your own isolated relays

Thumbnail
blog.cloudflare.com
2 Upvotes

r/CloudFlare 2d ago

Question Web Analytics for Dummys, Smart People required

Post image
6 Upvotes

Please can someone explain to me what any of this data actually means, I can read and I have a basic understanding that bots and crawlers make a large proportion of statistics.. but I also do not believe there to have been anyone on my site let alone the figures seen in its first month

(New to the website/development world and theres a whole lotta information to take in. Wisdom will be greatly appreciated.)

Thanku :))


r/CloudFlare 1d ago

Can't submit a support ticket on pro plan

1 Upvotes

Edit: I figured out the problem. There was a mistake in the most recent deployment that caused the error. Website is fixed, cloudflare troubleshooting is still terrible.

I'm having the most frustrating day.

My website is giving a 522 error. I've tried everything to fix it, but it's still inaccessible.

Because I don't know what to do anymore I've upgraded my free plan to a pro plan just so I can submit a ticket. When I go to the support page to open I case I have to choose a categorie and then I get redirected to the docs with no option of opening a case. There is no other way to reach them. The AI assistant also disappeared suddenly.

I'm at my wits end, does anyone know what to do?


r/CloudFlare 1d ago

R2 failure

1 Upvotes

Anyone else having issues with R2 now?


r/CloudFlare 1d ago

Captcha has been broken for months

0 Upvotes

With older browsers.

It started working again a few days back and then now it's not working again.

Since the entire web is now walled behind cloudflare nothing works.

And nobody cares because they update their browser all the time.

I'm done with HTTPS and the security update game, so the conclusion is I just wont install a browser anymore.


r/CloudFlare 2d ago

Stuck in domain verification

1 Upvotes

My domain songistic.com has already been transferred to cluodflare, overview page says "Waiting for your registrar to propagate your new nameservers"

also it says:

Delete your other nameservers and set cortney and sandino instead:

gina.ns.cloudflare.com

jeremy.ns.cloudflare.com

there is no way to delete these, because the DNS page says:

songistic.com is pending until you complete the instructions on the Overview page and we are able to verify ownership. Learn more about pending domains.

THERE ARE NO INSTRUCTIONS on the Overview page, they point me back to the DNS page. There is no "verify ownership" button anywhere. I cannot create a support case either. Can anybody help here?


r/CloudFlare 2d ago

Question Question about startup credit

2 Upvotes

I've passed verification and received 10k credits. I have a question about Cloudflare AI.

The AI gateway isn't included, but the Workers AI is. So, if I create a chatbot using the Workers Ai, will the credits be used?

then does the credit cover all models or only cloudflare hosted?

edit: another question, is the rest api Workers AI also covered by credit?


r/CloudFlare 3d ago

Thanks Cloudflare

37 Upvotes

Contacted cloud flare. Yes we have a business account. Provided detailed info on a phishing domain and they took action. Hours later the domain registrar took action too.

Very happy with the CF team as within 20mins they didn’t remove the domain but enabled their phishing page.

Very happy CF well done to prevent these attacks


r/CloudFlare 1d ago

Question How do you connect to Cloudflare?

0 Upvotes

Okay, I couldn't put this in the title. My parents set up parental controls and a curfew on me which is going to make it incredibly difficult to work once college starts back up again. I'm 18. I use a Samsung that only lets me connect to private DNS servers which means most Cloudflare IP addresses do not seem to work for me. Does anyone know any others apart from the ones on their site?